CWE-1236
Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
283 vulnerabilities with CWE-1236
CVE-2023-31294
HIGH
Sesami CPTO <6.3.8.6 - Info Disclosure
CVSS 7.5
CVE-2023-50448
MEDIUM
ActiveAdmin <2.12.0 - Info Disclosure
CVSS 6.5
CVE-2023-51763
CRITICAL
ActiveAdmin <3.2.0 - Code Injection
CVSS 9.8
CVE-2023-48207
HIGH
Availability Booking Calendar 5.0 - Code Injection
CVSS 8.8
CVE-2023-42004
HIGH
IBM Security Guardium <11.6 - Code Injection
CVSS 8.0
CVE-2023-48029
HIGH
Corebos <8.0 - Code Injection
CVSS 8.0
CVE-2023-41798
MEDIUM
wpWax Directorist - Improper Neutralization of Formula Elements
CVSS 5.1
CVE-2023-36527
MEDIUM
BestWebSoft Post to CSV <1.4.0 - Info Disclosure
CVSS 4.7
CVE-2023-25983
HIGH
WPOmnia KB Support <1.5.84 - Info Disclosure
CVSS 8.8
CVE-2023-23796
MEDIUM
Muneeb Form Builder <1.9.9.0 - Info Disclosure
CVSS 4.7
CVE-2023-23678
MEDIUM
WPEkaClub WP Cookie Consent <2.2.5 - Info Disclosure
CVSS 4.0
CVE-2023-22719
MEDIUM
GiveWP <2.25.1 - Info Disclosure
CVSS 4.7
CVE-2023-43071
MEDIUM
Dell SmartFabric Storage Software <1.4 - XSS
CVSS 4.4
CVE-2023-22877
HIGH
IBM InfoSphere Information Server 11.7 - Code Injection
CVSS 7.0
CVE-2023-38843
HIGH
Atlos <1.0 - Authenticated RCE
CVSS 8.0
CVE-2023-4006
CRITICAL
thorsten/phpmyfaq <3.1.16 - Info Disclosure
CVSS 9.8
CVE-2023-37219
HIGH
Tadiran Telecom Composit - SQL Injection
CVSS 7.3
CVE-2023-3527
MEDIUM
Avaya CMS Supervisor - Code Injection
CVSS 6.8
CVE-2023-28958
HIGH
IBM Watson Knowledge Catalog - Code Injection
CVSS 7.0
CVE-2023-3493
HIGH
fossbilling <0.5.3 - Info Disclosure
CVSS 8.0
CVE-2023-3302
HIGH
admidoi/admidio <4.2.9 - Info Disclosure
CVSS 7.8
CVE-2023-31867
HIGH
Sage X3 <12.14.0.50-0 - Code Injection
CVSS 7.2
CVE-2023-0721
HIGH
Metform Elementor Contact Form Builder <3.3.0 - Code Injection
CVSS 8.3
CVE-2023-33410
HIGH
Minical <1.0.0 - Code Injection
CVSS 8.8
CVE-2023-2629
HIGH
pimcore/customer-data-framework <3.3.9 - Info Disclosure
CVSS 7.8
Details
Vulnerabilities
283